Skip to main content

Privacy & Data Retention

Plan requirement

The Privacy page and retention settings require the Business plan, and are included in the 14-day trial.

Sielum monitors AI tool usage on employee workstations, which makes it subject to the works council and GDPR conversations every endpoint tool goes through. This page describes what is collected, what is deliberately not, and how long it is kept.

What Sielum never collects

This is the short list that usually decides the conversation:

  • AI prompt contents — what people type into an AI model
  • AI response contents — what the model answers
  • Contents of files an AI agent reads or writes
  • Browser history or screen content
  • Keystrokes or clipboard data
  • API key values (only the presence and the name of a key are detected)
  • Personal communications

Web AI detection matches the destination domain of a browser connection. No traffic is proxied, decrypted or inspected, so Sielum can report that a browser talked to a web AI service, never what was said.

What is collected

CategoryExamplesKept for
Process informationProcess name, CPU and memory usage, the user running itRetention window
Network connectionsDestination domain, remote address, connection stateRetention window
AI tool configurationMCP server names, tool lists, transport typeRetention window
Endpoint metadataHostname, operating system, internal IP, last seenLifetime of the device
Security alertsMessage, severity, status, timestampRetention window
Audit logAdmin action, affected resource, user ID, timestampKept as a compliance record

The dashboard exposes this as a machine-readable data map under Privacy, including the legal basis recorded per category, so you can attach it to a processing record instead of rewriting it.

Retention

Telemetry is purged automatically once it passes your retention window.

  • Default: 7 days
  • Maximum: 30 days — the server rejects a higher value

Set the window under Privacy in the dashboard. It applies to all telemetry tables, including connection events. Endpoint metadata and the audit log are not telemetry and are kept as described in the table above.

Retention and reports

An export can only contain what still exists. If you need a 90-day report, a 7-day retention window cannot produce it — decide the retention setting with your reporting period in mind, see Reports.

Deleting a single endpoint's data

Under Devices, an admin can delete all collected data for one endpoint. This is the mechanism for a deletion request covering one person's workstation, and it removes the telemetry rather than hiding it.

Where the data lives

All data stays in PostgreSQL inside your Sielum deployment. Sielum SaaS runs in the EU (Germany) and no telemetry is transferred to a third-party cloud. The organization deploying Sielum is the controller under GDPR Art. 4(7).